MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 241937fdff6aeae4c5a60bc707c331504d4b5c8df13b97ddd2e8da2107978f0e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 241937fdff6aeae4c5a60bc707c331504d4b5c8df13b97ddd2e8da2107978f0e
SHA3-384 hash: 6172332b4f3dd8990d181f2571af91b2858c5ea70dcf4ee53165b64731c8720c770d902d556a42495e1491395bc2461a
SHA1 hash: aa2adf240ec8373f129ee4c090c03bf254325b91
MD5 hash: 5bda56bf95a4cc0997bdb896cc581b65
humanhash: juliet-artist-grey-spaghetti
File name:PI 46788393.zip
Download: download sample
Signature Formbook
File size:364'134 bytes
First seen:2020-06-16 13:09:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:xYwe7Qv8sfQ8idStirZytid2Y88QqbOa4GhpOPS/ArIljksadMCkaA2vUhUXC:qwe7QNfeStAZ+q2YccOafoq/EIisaOaK
TLSH 9A7423CFC2CB1795F90512BFA5A1AE0ADFD870AEDC905C836E40484DF6CEE807969649
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing Formbook:

HELO: vps.sandrovicari.cc
Sending IP: 45.95.169.67
From: Bella Peng <info@sandrovicari.cc>
Subject: Revised PI 46788393
Attachment: PI 46788393.zip (contains "PI 46788393.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-16 13:11:05 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

zip 241937fdff6aeae4c5a60bc707c331504d4b5c8df13b97ddd2e8da2107978f0e

(this sample)

  
Dropping
Formbook
  
Delivery method
Distributed via e-mail attachment

Comments